mirror of https://github.com/dotnet/tye.git
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
111 lines
4.4 KiB
111 lines
4.4 KiB
// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.
|
|
// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.
|
|
|
|
|
|
using IdentityServer4;
|
|
using IdentityServerHost.Quickstart.UI;
|
|
using Microsoft.AspNetCore.Builder;
|
|
using Microsoft.AspNetCore.Hosting;
|
|
using Microsoft.Extensions.Configuration;
|
|
using Microsoft.Extensions.DependencyInjection;
|
|
using Microsoft.Extensions.Hosting;
|
|
using IdentityServer4.Models;
|
|
using System.Collections.Generic;
|
|
using System;
|
|
using IdentityServer4.Services;
|
|
using Microsoft.Extensions.Logging.Abstractions;
|
|
using Microsoft.Extensions.Logging;
|
|
|
|
namespace IdentityServer
|
|
{
|
|
public class Startup
|
|
{
|
|
public IWebHostEnvironment Environment { get; }
|
|
public IConfiguration Configuration { get; }
|
|
|
|
public Startup(IWebHostEnvironment environment, IConfiguration configuration)
|
|
{
|
|
Environment = environment;
|
|
Configuration = configuration;
|
|
}
|
|
|
|
public void ConfigureServices(IServiceCollection services)
|
|
{
|
|
services.AddControllersWithViews();
|
|
services.AddSingleton<DefaultCorsPolicyService>((sp) =>
|
|
{
|
|
return new DefaultCorsPolicyService(sp.GetRequiredService<ILogger<DefaultCorsPolicyService>>()){AllowAll = true};
|
|
});
|
|
|
|
var builder = services.AddIdentityServer(options =>
|
|
{
|
|
options.Events.RaiseErrorEvents = true;
|
|
options.Events.RaiseInformationEvents = true;
|
|
options.Events.RaiseFailureEvents = true;
|
|
options.Events.RaiseSuccessEvents = true;
|
|
|
|
// see https://identityserver4.readthedocs.io/en/latest/topics/resources.html
|
|
options.EmitStaticAudienceClaim = true;
|
|
})
|
|
.AddTestUsers(TestUsers.Users);
|
|
|
|
// in-memory, code config
|
|
builder.AddInMemoryIdentityResources(Config.IdentityResources);
|
|
builder.AddInMemoryApiScopes(Config.ApiScopes);
|
|
Console.WriteLine(Configuration.GetServiceUri("results:https"));
|
|
builder.AddInMemoryClients(new Client[]
|
|
{
|
|
// m2m client credentials flow client
|
|
// interactive client using code flow + pkce
|
|
new Client
|
|
{
|
|
ClientId = "interactive",
|
|
ClientSecrets = { new Secret("49C1A7E1-0C79-4A89-A3D6-A37998FB86B0".Sha256()) },
|
|
|
|
AllowedGrantTypes = GrantTypes.Code,
|
|
|
|
RedirectUris = { $"{Configuration.GetServiceUri("results:https")}/signin-oidc/" },
|
|
FrontChannelLogoutUri = $"{Configuration.GetServiceUri("results:https")}/signout-oidc/",
|
|
PostLogoutRedirectUris = { $"{Configuration.GetServiceUri("results:https")}/signout-callback-oidc/" },
|
|
|
|
AllowOfflineAccess = true,
|
|
// AllowedCorsOrigins = { $"{Configuration.GetServiceUri("results:https")}" },
|
|
AllowedScopes = new List<string>{IdentityServerConstants.StandardScopes.OpenId,IdentityServerConstants.StandardScopes.Profile}
|
|
},
|
|
});
|
|
|
|
// not recommended for production - you need to store your key material somewhere secure
|
|
builder.AddDeveloperSigningCredential();
|
|
|
|
services.AddAuthentication()
|
|
.AddGoogle(options =>
|
|
{
|
|
options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;
|
|
|
|
// register your IdentityServer with Google at https://console.developers.google.com
|
|
// enable the Google+ API
|
|
// set the redirect URI to https://localhost:5001/signin-google
|
|
options.ClientId = "copy client ID from Google here";
|
|
options.ClientSecret = "copy client secret from Google here";
|
|
});
|
|
}
|
|
|
|
public void Configure(IApplicationBuilder app)
|
|
{
|
|
if (Environment.IsDevelopment())
|
|
{
|
|
app.UseDeveloperExceptionPage();
|
|
}
|
|
|
|
app.UseStaticFiles();
|
|
|
|
app.UseRouting();
|
|
app.UseIdentityServer();
|
|
app.UseAuthorization();
|
|
app.UseEndpoints(endpoints =>
|
|
{
|
|
endpoints.MapDefaultControllerRoute();
|
|
});
|
|
}
|
|
}
|
|
}
|